Skip to content

fix(cve): CVE-2026-75143 - avformat/librist: honor the caller buffer size in librist_read - #43

Merged
lzwind merged 22 commits into
masterfrom
fix-cve/CVE-2026-75143
Sep 22, 2026
Merged

lzwind merged 22 commits into
masterfrom
fix-cve/CVE-2026-75143

Conversation

@deepin-ci-robot

@deepin-ci-robot deepin-ci-robot commented Sep 20, 2026 •

Copy link
Copy Markdown
Contributor

CVE: CVE-2026-75143 (critical) - librist_read() ignored its size argument and copied the full payload_len, overflowing a smaller destination. Clamp the copy to the caller-provided buffer size.
Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1c10bcc2e17255dacb717a25ab3db142ce390602.patch

Co-authored-by: hudeng hudeng@deepin.org
Generated-By: qwen3.6-35b


CVE: CVE-2026-66038 (high) - avcodec/lcldec: zero the not-decoded tail to avoid heap disclosure
Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/e7cbfd1c507b57a806a5825b87d609963e862c8c.patch

Co-authored-by: hudeng hudeng@deepin.org
Generated-By: qwen3.6-35b


CVE: CVE-2026-65704 - 兼容性适配修改:添加 libavutil/macros.h 头文件以提供 FFMIN 宏定义

Co-authored-by: hudeng hudeng@deepin.org
Generated-By: qwen3.6-35b


CVE: CVE-2026-70632 (high) - cfhd 解码器中拒绝 transform-2 输出宽度大于平面的情况,修复数组越界访问
Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/16b2049d4d5222db6cd7c031409058571c94f6a9.patch

Co-authored-by: hudeng hudeng@deepin.org
Generated-By: qwen3.6-35b


CVE: CVE-2026-75146 (high) - FFmpeg before commit 65b0dab contains an out-of-bounds read in the DASH demuxer (libavformat/dashdec.c). When a live DASH manifest is refreshed with a startNumber that is lower than the previous value, the current sequence number is driven negative. The fragment retrieval function checked only the upper bound, allowing negative indices to access invalid memory.
Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/65b0dab903e5975e036b30ecc58f5935d4f151e0

Co-authored-by: hudeng hudeng@deepin.org
Generated-By: qwen3.6-35b


CVE: CVE-2026-65703 (high) - tdsc 解码器数组越界访问漏洞
Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/fd3ee52fab34d98a95b787d0b5ff45685766200c

Co-authored-by: hudeng hudeng@deepin.org
Generated-By: qwen3.6-35b


CVE: CVE-2026-65705 (high) - FFmpeg versions 3.4 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_floodfill video filter that allows attackers to corrupt heap memory by supplying a dynamically sized video stream with filtergraph reinitialization disabled via -reinit_filter 0.
Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/f186c50cf53aec20e9a29059cb22ca3f2d59201c

Co-authored-by: hudeng hudeng@deepin.org
Generated-By: qwen3.6-35b

…size in librist_read

CVE: CVE-2026-75143 (critical) - librist_read() ignored its size argument and copied the full payload_len, overflowing a smaller destination. Clamp the copy to the caller-provided buffer size.
Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1c10bcc2e17255dacb717a25ab3db142ce390602.patch

Co-authored-by: hudeng <hudeng@deepin.org>
Generated-By: qwen3.6-35b
@deepin-ci-robot

Copy link
Copy Markdown
Contributor Author

/hold
因为该quilt包的上游版本号变更,详情见: deepin-community/infra-settings#134

@github-actions

Copy link
Copy Markdown

TAG Bot

TAG: 7%6.1.5-0deepin9
EXISTED: no
DISTRIBUTION: unstable

@deepin-ci-robot

Copy link
Copy Markdown
Contributor Author

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by:
Once this PR has been reviewed and has the lgtm label, please assign yukarichiba for approval. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

deepin-ci-robot and others added 19 commits September 21, 2026 00:47
…to avoid heap disclosure

CVE: CVE-2026-66038 (high) - avcodec/lcldec: zero the not-decoded tail to avoid heap disclosure
Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/e7cbfd1c507b57a806a5825b87d609963e862c8c.patch

Co-authored-by: hudeng <hudeng@deepin.org>
Generated-By: qwen3.6-35b
…m underflow the packet size

CVE: CVE-2026-65704 (high) - FFmpeg through 8.1.2 contains an out-of-bounds write vulnerability that allows attackers to cause heap corruption by supplying a crafted ffconcat file processed with the -safe 0 flag. The TY demuxer's demux_audio() function decrements packet size without bounds checking, producing a negative size value.
Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/de771bd52774a52d45b0e2c82e56995a1ef40df7

Co-authored-by: hudeng <hudeng@deepin.org>
Generated-By: qwen3.6-35b
CVE: CVE-2026-65704 - 兼容性适配修改:添加 libavutil/macros.h 头文件以提供 FFMIN 宏定义

Co-authored-by: hudeng <hudeng@deepin.org>
Generated-By: qwen3.6-35b
…der than the plane

CVE: CVE-2026-70632 (high) - cfhd 解码器中拒绝 transform-2 输出宽度大于平面的情况,修复数组越界访问
Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/16b2049d4d5222db6cd7c031409058571c94f6a9.patch

Co-authored-by: hudeng <hudeng@deepin.org>
Generated-By: qwen3.6-35b
…nt index

CVE: CVE-2026-75146 (high) - FFmpeg before commit 65b0dab contains an out-of-bounds read in the DASH demuxer (libavformat/dashdec.c). When a live DASH manifest is refreshed with a startNumber that is lower than the previous value, the current sequence number is driven negative. The fragment retrieval function checked only the upper bound, allowing negative indices to access invalid memory.
Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/65b0dab903e5975e036b30ecc58f5935d4f151e0

Co-authored-by: hudeng <hudeng@deepin.org>
Generated-By: qwen3.6-35b
…fore reallocating on size chan

CVE: CVE-2026-65703 (high) - tdsc 解码器数组越界访问漏洞
Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/fd3ee52fab34d98a95b787d0b5ff45685766200c

Co-authored-by: hudeng <hudeng@deepin.org>
Generated-By: qwen3.6-35b
…t overflow the system header

CVE: CVE-2026-75142 (high) - mpegenc: reject stream counts that overflow the system header
Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/9d786e4b5e9b8482651928574de33772aeee7be1,https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/b274f0d21ba684446fd59b49e00f3f8e9ed954df

Co-authored-by: hudeng <hudeng@deepin.org>
Generated-By: qwen3.6-35b
…ffer for the widest plane

CVE: CVE-2026-65706 (high) - avfilter/vf_swaprect: size the temp row buffer for the widest plane - out of array access
Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a7e38b617b32f996beaa371bbf04b39907d7a527

Co-authored-by: hudeng <hudeng@deepin.org>
Generated-By: qwen3.6-35b
…ow in the capacity check

CVE: CVE-2026-70628 (high) - dvbsub_parser 中容量检查的有符号整数溢出漏洞
Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/93f2a525ec6c7b467bae68322720d10188fc6e30.patch

Co-authored-by: hudeng <hudeng@deepin.org>
Generated-By: qwen3.6-35b
… overflow the 16-bit count

CVE: CVE-2026-75141 (high) - 整数溢出导致数组越界访问
Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/acf5d7cdc1f9ae8752c23e1ea8d7f355ed780781.patch

Co-authored-by: hudeng <hudeng@deepin.org>
Generated-By: qwen3.6-35b
…arger than the RTP payload buf

CVE: CVE-2026-75144 (high) - rtpenc_vc2hq: reject data units larger than the RTP payload buffer
Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1cdeb3c4e7f1f8566d846b9b451e01c376398818.patch

Co-authored-by: hudeng <hudeng@deepin.org>
Generated-By: qwen3.6-35b
…aller than their header

CVE: CVE-2026-64834 (high) - FFmpeg versions 0.6.3 through 8.1.2 contain an infinite loop vulnerability in the RTP/ASF demuxer within libavformat/rtpdec_asf.c that allows remote attackers to cause denial of service by sending a crafted RTP/ASF stream.
Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/11d5f475be95d22d5f0692220cc772b116abc632

Co-authored-by: hudeng <hudeng@deepin.org>
Generated-By: qwen3.6-35b
…d bound the stream count

CVE: CVE-2026-64830 (high) - 堆缓冲区溢出漏洞在 vobsub 字幕处理中
Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/dbd495f066a85ba96b17433f4306582aa37c3951.patch

Co-authored-by: hudeng <hudeng@deepin.org>
Generated-By: qwen3.6-35b
…r than the strip

CVE: CVE-2026-70631 (medium) - avcodec/tiff: reject inflate output shorter than the strip - use of uninitialized memory
Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/2f234ea34c81288e3840fca632dd16481d8de39f

Co-authored-by: hudeng <hudeng@deepin.org>
Generated-By: qwen3.6-35b
…ta when the input is too short

CVE: CVE-2026-70629 (medium) - 修复 rscc 解码器中的堆溢出写入漏洞
Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/cd1f545cf27ba08f6f5b31b1e92665d7874d4fd7

Co-authored-by: hudeng <hudeng@deepin.org>
Generated-By: qwen3.6-35b
CVE: CVE-2026-70629 - 兼容性适配修改:无额外兼容性问题,直接应用 CVE 修复补丁

Co-authored-by: hudeng <hudeng@deepin.org>
Generated-By: qwen3.6-35b
…can_seek_to_key_sample()

CVE: CVE-2026-13858 (medium) - Fix negative index given to can_seek_to_key_sample()
Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/cb8a5ca8ab36884064ac4de5175ae82c93edfcb2.patch

Co-authored-by: hudeng <hudeng@deepin.org>
Generated-By: qwen3.6-35b
CVE: CVE-2026-66040 (high) - fix overrun caused by exif size discrepancy
The overrun that upstream b506fafec9 hardens lives in the eXIf chunk writer of
libavcodec/pngenc.c, which sizes the chunk from ff_exif_get_buffer() with
AV_EXIF_TIFF_HEADER. Neither the helper nor AV_FRAME_DATA_EXIF exists in FFmpeg
6.1.5 - pngenc.c in this package never writes an eXIf chunk at all, EXIF output
support was added after the 6.1 branch. The patch generated for this CVE
therefore cannot be applied here: it referenced APIs that do not exist and
broke the build with "implicit declaration of function 'ff_exif_get_buffer'"
and "'AV_EXIF_TIFF_HEADER' undeclared". No patch required; recorded for the
security tracker.

Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/b506fafec9a19fcbc2be5271875fd4a63d6615bc.patch

Co-authored-by: hudeng <hudeng@deepin.org>
Generated-By: qwen3.6-35b
The x86_64 FATE run fails for fate-vsynth1/2/3-ffv1-2pass,
ffv1-v3-yuv422p10, ffv1-v3-yuv444p16 and ffv1-v3-rgb48.

debian/rules builds with --toolchain=hardened, which makes configure add
-fstack-protector-all. Together with -O3 this makes gcc (12 and 13 alike)
miscompile the branchy form of renorm_encoder() that libavcodec/rangecoder.h
still carries on the 6.1 branch, so the FFV1 range coder writes a corrupt
extradata: the pass-1 stream is byte identical except that the FFV1 extradata
grows from 190 to 298 bytes and the decoder rejects it with
"quant_table_index out of range". aarch64 is unaffected because it does not
get -fstack-protector-all here.

Backport upstream b2da4c33e31f85b9c755f2cdb08f5db694e90ca9, which rewrites
renorm_encoder() without the c->outstanding_byte < 0 shortcut. The generated
bitstream is unchanged: the reference hashes are identical with and without
-fstack-protector-all.

Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/b2da4c33e31f85b9c755f2cdb08f5db694e90ca9

Co-authored-by: hudeng <hudeng@deepin.org>
Generated-By: qwen3.6-35b
@hudeng-go

Copy link
Copy Markdown
Contributor

PR #44 has been merged into this branch (8fbb6edc), so #43 now carries both CVE sets.

Merged in (cherry-picked, branch stays linear for tide):
CVE-2026-75142, CVE-2026-65706, CVE-2026-70628, CVE-2026-75141, CVE-2026-75144,
CVE-2026-64834, CVE-2026-64830, CVE-2026-70631, CVE-2026-70629, CVE-2026-13858.

CVE-2026-66040 is recorded as not-affected rather than patched: the eXIf
chunk writer that upstream b506fafec9 hardens does not exist in 6.1.5
(ff_exif_get_buffer() / AV_EXIF_TIFF_HEADER / AV_FRAME_DATA_EXIF were all
added after the 6.1 branch), so the generated patch only broke the build.
See #44 for the full analysis.

Also fixed here: the pre-existing x86_64 FATE failure.

Before this update, PR-42 and master already failed 12 FFV1 FATE tests on
x86_64 only (fate-vsynth1/2/3-ffv1-2pass, ffv1-v3-yuv422p10,
ffv1-v3-yuv444p16, ffv1-v3-rgb48); no CVE patch touches ffv1enc.c.
Root cause: debian/rules builds with --toolchain=hardened, so configure
adds -fstack-protector-all; together with -O3 that makes gcc (12 and 13)
miscompile the branchy form of renorm_encoder() still present on the 6.1
branch. The FFV1 range coder then writes a corrupt extradata (190 → 298 bytes)
that the decoder rejects with quant_table_index out of range. aarch64 is
unaffected because it does not get -fstack-protector-all.

Backported upstream b2da4c33e31f85b9c755f2cdb08f5db694e90ca9, which rewrites
renorm_encoder() without the c->outstanding_byte < 0 shortcut. It is a pure
refactoring — the bitstream and the FATE reference hashes are unchanged — and
the 12 failing tests now pass with -fstack-protector-all.

Verified on this branch: 27 patches apply cleanly, build clean, full FATE
suite green.

deepin-ci-robot and others added 2 commits September 21, 2026 21:46
…iables

CVE: CVE-2026-65705 (high) - FFmpeg versions 3.4 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_floodfill video filter that allows attackers to corrupt heap memory by supplying a dynamically sized video stream with filtergraph reinitialization disabled via -reinit_filter 0.
Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/f186c50cf53aec20e9a29059cb22ca3f2d59201c

Co-authored-by: hudeng <hudeng@deepin.org>
Generated-By: qwen3.6-35b
1. CVE-2026-65704: fix Origin field from N/A to upstream commit URL
   (de771bd), update Description to proper security fix description
   explaining the 6.1.5 backport adaptation (FFMIN macro header).

2. CVE-2026-70629: fix Origin field from N/A to upstream commit URL
   (cd1f545), align with changelog reference.

3. CVE-2026-13858: add runtime guard (if (sample < 0) return 1) before
   av_assert0 so a negative index returns a safe default instead of
   crashing, providing defense-in-depth beyond the always-on av_assert0.
@lzwind
lzwind merged commit c589a75 into master Sep 22, 2026
4 of 5 checks passed
@Zeno-sole

Copy link
Copy Markdown
Contributor

/integrate

@github-actions

Copy link
Copy Markdown

AutoIntegrationPr Bot
auto integrate with pr url: deepin-community/Repository-Integration#4601
PrNumber: 4601
PrBranch: auto-integration-35943593554

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants